VulnSea

Tagged “osv”

CVEs tagged osv, newest first.

5683 CVEsRSS

CVE-2026-40264Low
5mo ago

OpenBao's Token Store Allows Cross-Namespace Renewal, Revocation

OpenBao's Token Store Allows Cross-Namespace Renewal, Revocation

▾ Sunlitopenbao · github.com/openbao/openbaoEPSS 0.36%via OSV
CVE-2026-39388Low· 3.1
5mo ago

OpenBao's Certificate Authentication Allows Token Renewal With Different Certificate

OpenBao's Certificate Authentication Allows Token Renewal With Different Certificate

▾ Sunlitopenbao · github.com/openbao/openbaoEPSS 0.14%via OSV
CVE-2026-39946Medium· 4.9
5mo ago

OpenBao's SQL Injection in PostgreSQL database secrets engine

OpenBao's SQL Injection in PostgreSQL database secrets engine

▾ Sunlitopenbao · github.com/openbao/openbaoEPSS 0.39%via OSV
CVE-2026-40890High· 7.5
5mo ago

github.com/gomarkdown/markdown: github.com/gomarkdown/markdown: Denial of Service via malformed Markdown input (CVE-2026-40890)

A flaw was found in github.com/gomarkdown/markdown, a Go library for parsing Markdown text and rendering as HTML. A remote attacker could exploit this vulnerability by providing a specially crafted malformed input. Specifically, input cont…

▾ TwilightRed Hat · Multicluster Global Hub 1.4.9EPSS 0.52%via CSAF
CVE-2026-28684Medium· 6.6
5mo ago

python-dotenv: Symlink following in set_key allows arbitrary file overwrite via cross-device rename fallback

python-dotenv: Symlink following in set_key allows arbitrary file overwrite via cross-device rename fallback

▾ Sunlitpython-dotenv · python-dotenvEPSS 0.19%via OSV
CVE-2026-35588Medium· 6.3
5mo ago

Glances has CQL Injection in its Cassandra Export Module via Unsanitized Config Values

Glances has CQL Injection in its Cassandra Export Module via Unsanitized Config Values

▾ Sunlitglances · glancesEPSS 0.19%via OSV
CVE-2026-34839Medium· 6.5
5mo ago

Glances: Cross-Origin Information Disclosure via Unauthenticated REST API (/api/4) due to Permissive CORS

Glances: Cross-Origin Information Disclosure via Unauthenticated REST API (/api/4) due to Permissive CORS

▾ Sunlitglances · glancesEPSS 0.47%via OSV
CVE-2026-35587High· 8.8
5mo ago

Glances has SSRF in IP Plugin via public_api leading to credential leakage

Glances has SSRF in IP Plugin via public_api leading to credential leakage

▾ Twilightglances · glancesEPSS 0.47%via OSV
CVE-2026-39378Medium· 6.5
5mo ago

nbconvert has an Arbitrary File Read via Path Traversal in HTMLExporter Image Embedding

nbconvert has an Arbitrary File Read via Path Traversal in HTMLExporter Image Embedding

▾ Sunlitnbconvert · nbconvertEPSS 0.46%via OSV
CVE-2026-33626High· 7.5PoC
5mo ago

LMDeploy has Server-Side Request Forgery (SSRF) via Vision-Language Image Loading

LMDeploy has Server-Side Request Forgery (SSRF) via Vision-Language Image Loading

▾ Midnightlmdeploy · lmdeployEPSS 1.5%via GHSA
CVE-2026-39377Medium· 6.5
5mo ago

nbconvert has an Arbitrary File Write via Path Traversal in Cell Attachment Filenames

nbconvert has an Arbitrary File Write via Path Traversal in Cell Attachment Filenames

▾ Sunlitnbconvert · nbconvertEPSS 0.40%via OSV
CVE-2026-6634Medium· 6.3
5mo ago

Memos has an Incorrect Privilege Assignment issue

Memos has an Incorrect Privilege Assignment issue

▾ Sunlitusememos · github.com/usememos/memosEPSS 0.35%via OSV
MAL-2026-2958None
5mo ago

Malicious code in mysten_metrics (crates.io)

Malicious code in mysten_metrics (crates.io)

▾ Sunlitmysten-metrics · mysten-metricsvia OSV
CVE-2026-6596High· 7.3
5mo ago

Langflow: DoS Through Lack of File Size Restriction via Deprecated Unauthenticated File Upload API

Langflow: DoS Through Lack of File Size Restriction via Deprecated Unauthenticated File Upload API

▾ Twilightlangflow-base · langflow-baseEPSS 0.47%via OSV
CVE-2026-6599Medium· 6.3
5mo ago

Langflow vulnerable to injection

Langflow vulnerable to injection

▾ Sunlitlangflow · langflowEPSS 0.39%via OSV
CVE-2025-66335Medium· 5.3
5mo ago

Apache Doris MCP Server vulnerable to SQL Injection via improper query context neutralization

Apache Doris MCP Server vulnerable to SQL Injection via improper query context neutralization

▾ Sunlitdoris-mcp-server · doris-mcp-serverEPSS 0.66%via OSV
CVE-2026-6608Medium· 5.3
5mo ago

FastChat has a Content Moderation Bypass via Arena Side-by-Side Views

FastChat has a Content Moderation Bypass via Arena Side-by-Side Views

▾ Sunlitfschat · fschatEPSS 0.51%via OSV
CVE-2026-6606High· 7.3
5mo ago

AgentScope vulnerable to Server-Side Request Forgery

AgentScope vulnerable to Server-Side Request Forgery

▾ Twilightagentscope · agentscopeEPSS 0.47%via OSV
CVE-2026-6603High· 7.3
5mo ago

AgentScope Vulnerable to Remote Code Injection

AgentScope Vulnerable to Remote Code Injection

▾ Twilightagentscope · agentscopeEPSS 0.52%via OSV
CVE-2026-6598Medium· 4.3
5mo ago

Langflow: Cleartext Storage of Authentication Settings in Project Creation Endpoint

Langflow: Cleartext Storage of Authentication Settings in Project Creation Endpoint

▾ Sunlitlangflow · langflowEPSS 0.24%via OSV
CVE-2026-6605High· 7.3
5mo ago

AgentScope vulnerable to Server-Side Request Forgery

AgentScope vulnerable to Server-Side Request Forgery

▾ Twilightagentscope · agentscopeEPSS 0.51%via OSV
CVE-2026-6604High· 7.3
5mo ago

AgentScope vulnerable to Server-Side Request Forgery

AgentScope vulnerable to Server-Side Request Forgery

▾ Twilightagentscope · agentscopeEPSS 0.47%via OSV
CVE-2026-6597Low· 2.7
5mo ago

Langflow has an Information Leak through Incomplete API Key Redaction

Langflow has an Information Leak through Incomplete API Key Redaction

▾ Sunlitlangflow · langflowEPSS 0.38%via OSV
CVE-2026-6607Medium· 5.3
5mo ago

FastChat has Denial of Service Through Blocking Event Loop in Model Workers (Incomplete Fix for ff66426)

FastChat has Denial of Service Through Blocking Event Loop in Model Workers (Incomplete Fix for ff66426)

▾ Sunlitfschat · fschatEPSS 0.74%via OSV
CVE-2026-3219Medium
5mo ago

pip has an interpretation conflict due to handling both concatenated tar and ZIP files as ZIP files

pip has an interpretation conflict due to handling both concatenated tar and ZIP files as ZIP files

▾ Sunlitpip · pipEPSS 0.18%via OSV
MAL-2026-2947None
5mo ago

Malicious code in moonbit-schema-utils (PyPI)

Malicious code in moonbit-schema-utils (PyPI)

▾ Sunlitmoonbit-schema-utils · moonbit-schema-utilsvia OSV
MAL-2026-2946None
5mo ago

Malicious code in moonbit-metrics-validator (PyPI)

Malicious code in moonbit-metrics-validator (PyPI)

▾ Sunlitmoonbit-metrics-validator · moonbit-metrics-validatorvia OSV
MAL-2026-2945None
5mo ago

Malicious code in moonbit-locale-compat (PyPI)

Malicious code in moonbit-locale-compat (PyPI)

▾ Sunlitmoonbit-locale-compat · moonbit-locale-compatvia OSV
CVE-2026-32690Low· 3.7
5mo ago

Apache Airflow Exposes Secrets in Variables Saved as JSON Dictionaries

Apache Airflow Exposes Secrets in Variables Saved as JSON Dictionaries

▾ Sunlitapache-airflow-core · apache-airflow-coreEPSS 0.66%via OSV
CVE-2026-30912Medium· 5.3
5mo ago

Apache Airflow exposes SQL stack trace despite "api/expose_stack_traces" set to false

Apache Airflow exposes SQL stack trace despite "api/expose_stack_traces" set to false

▾ Sunlitapache-airflow-core · apache-airflow-coreEPSS 0.76%via OSV
CVEs tagged “osv” — page 74 · VulnSea